Fun

News Feed - 2023-07-26 01:07:24

Tom Blackstone7 hours agoEra Lend on zkSync exploited for $3.4M in reentrancy attackThe lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.1128 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksLending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i— CertiK Alert (@CertiKAlert) July 25, 2023


According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.


Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.


On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM— Spreek (@spreekaway) July 25, 2023


Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.


Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.


In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”


To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.


Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Blockchain# Cryptocurrencies# Security# Ethereum# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to actually spend your Bitcoin, ExplainedTwitter vs. Threads: Users are the real losersZero-knowledge tech development heats up amid bear marketCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploitArbitrum-based Rodeo Finance exploited for second time, $1.5M stolen

News Feed

Bitcoin, Ethereum Technical Analysis: Bitcoin Moves Higher as Crypto Markets Rebound on Saturday
Bitcoin, Ethereum Technical Analysis: Bitcoin Moves Higher as Crypto Markets Rebound on Saturday Following two consecutive days of losses, bitcoin and ethereum both rebounded stron
ECB Hikes Interest Rates by 50bps; Signals Need for Further Hikes to Fight Inflation
ECB Hikes Interest Rates by 50bps; Signals Need for Further Hikes to Fight Inflation The European Central Bank (ECB) decided to hike three of its key interest rates by 50 basis poi
William SubergNov 04, 2023Bitcoin bulls defend $34K as trader predicts next BTC price ‘impulse’Bitcoin is setting up for another trip past $35,000, analysis argues, as BTC price settles into the weekend.18636 Total v
John McAfee Announces Privacy Coin – Airdrop Today
John McAfee Announces Privacy Coin – Airdrop Today2020 has been a turbulent year for the cryptocurrency market, but it has established the resilience of blockchain technology. Des
Cash2Bitcoin: As Bitcoin Greatly Outperforms S&P 500, Bitcoin ATMs Gain in Popularity
Cash2Bitcoin: As Bitcoin Greatly Outperforms S&P 500, Bitcoin ATMs Gain in Popularity sponsored Since the beginning of the COVID-19 pandemic and after an initial dip, the stock mark
Bitcoin miner reserves held steady in February, despite $40B flows to exchanges
Ana Paula Pereira4 hours agoBitcoin miner reserves held steady in February, despite $40B flows to exchangesBitcoin miners’ holdings remained stable in February at around 1.82 million BTC despite miners’ sales ahead o
Report: Nigeria Debt Management Office’s $48.8 Billion Debt Contravenes the Law Says Expert
Report: Nigeria Debt Management Office"s $48.8 Billion Debt Contravenes the Law Says Expert The Nigerian Debt Management Office (DMO) contravened the law when its borrowings exceed
Unicoin exec explains why projects fail — Blockchain Futurist Conference
Vince Quill4 hours agoUnicoin exec explains why projects fail — Blockchain Futurist ConferenceUnicoin hopes to launch on exchanges later this year and focuses on creating digital assets backed by investment portfolio w
Execs at crypto-friendly Evolve Bank leave amid regulatory crackdown: Report
Alex O’Donnell4 hours agoExecs at crypto-friendly Evolve Bank leave amid regulatory crackdown: ReportThe bank services several crypto-friendly financial technology companies.438 Total views5 Total sharesListen to artic
Bitcoin Price Risks Market Crash After Closing Below Final Weekly Resistance
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
‘Golden Boys’ behind Compound ‘governance attack’ agree to rescind proposal
Martin Young3 hours ago‘Golden Boys’ behind Compound ‘governance attack’ agree to rescind proposalA member of the “Golden Boys” voting bloc, Humpy, appears to have accepted a new staking proposal while agreei
Savannah Fortis14 hours agoGoogle sues scammers over creation of fake Bard AI chatbotGoogle has filed a lawsuit against scammers offering a malicious version of its AI chatbot Bard that tricks users into downloading and